Skip to content
Log inRegister
Criticalrisk levelConfirmedGCC/MENA relevance

SharePoint RCE (CVE-2026-45659) Is Being Actively Exploited -- Patch Now

Dr. Abeer Alshammari · Published 7/29/2026

Executive View

On-premises SharePoint servers are being actively exploited via a remote code execution flaw (CVSS 8.8) that requires only low-privilege authenticated access. A fix has existed since May 2026. Any organization still running unpatched on-premises SharePoint Server, Subscription Edition, 2019, or Enterprise 2016 should treat this as an immediate patching action, not a scheduling decision. Decision required: confirm patch status today; if unpatched, isolate or patch within 24 hours.

Vulnerability Intelligence

CVE
CVE-2026-45659
CVSS
8.8
Affected product
Microsoft SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016) -- SharePoint Online is not affected
Exploit status
Actively exploited
CISA KEV listed
Yes
Patch status
Patch available since May 2026; apply immediately if not already applied
Vendor advisory
Vendor advisory
CyberAbeer priorityImmediate

CyberAbeer's own prioritization guidance, based on severity, known exploitation, and exposure -- not an official vendor or CISA rating.

Sources last checked 7/29/2026

Developing story: CONFIRMED

CISA confirmed active exploitation and added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on July 1, 2026. A patch has been available since May 2026.

What happened

CISA added CVE-2026-45659, a Microsoft SharePoint Server deserialization-of-untrusted-data remote code execution vulnerability, to its KEV catalog on July 1, 2026, citing evidence of active exploitation. Microsoft shipped a patch in May 2026 but did not publicly disclose the vulnerability until May 21. Federal Civilian Executive Branch agencies were given until July 4, 2026 to remediate.

Why it matters

The flaw does not require administrator privileges: an authenticated attacker with only Site Member-level access can trigger remote code execution in a low-complexity attack that needs no user interaction. Combined with a roughly six-week gap between patch availability and public disclosure, many organizations plausibly have not yet applied it.

Who is affected

Organizations running on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, or SharePoint Enterprise Server 2016. SharePoint Online (Microsoft-managed) is not affected -- this is specifically a self-hosted patching problem.

Technical impact

FieldDetail
CVECVE-2026-45659
CVSS8.8
Vulnerability typeDeserialization of untrusted data -> remote code execution
Privileges requiredLow (authenticated Site Member)
User interactionNone
CISA KEVAdded July 1, 2026
Patch availabilityMay 2026 (disclosed May 21, 2026)

Governance impact

This is a patch-management control failure pattern, not a novel attack technique: the fix existed for weeks before exploitation was confirmed. Organizations should treat the gap between "patch available" and "patch applied" as a tracked metric with an owner, not an assumption.

What security teams should do

  • Confirm patch status on every on-premises SharePoint Server instance today
  • If unpatched, apply the May 2026 update immediately or isolate the server from untrusted networks
  • Review SharePoint server logs for indicators of exploitation predating patching
  • Confirm SharePoint Online is correctly excluded from this exposure in your asset inventory

What executives should know

A working fix has existed for months. The organizational risk now is entirely about how quickly known patches get applied to internet-facing, business-critical systems -- a process and accountability question, not a technology gap.

Dr. Abeer Takeaway

The decision this forces is not "should we patch" -- it is "who owns confirming patch status on every SharePoint instance, and by when." If that owner and deadline do not already exist, this is the control gap to close, independent of this specific CVE.

GCC Relevance

On-premises SharePoint remains widely deployed across GCC government and enterprise environments, including in sectors with lower cloud-migration rates. Confirm exposure specifically for on-premises deployments rather than assuming Microsoft 365/SharePoint Online coverage applies.

Back to Cyber Intelligence